This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New To Forum

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, well my system is not running as it should sinci i had the virus cleaned and removed so im not real sure what i should do. Its running ok but when i open up my spydoctor to run scans it takes forever for it to open and sometimes doesnt open. Its seems to have affected msn when i am in calls it cancels the calls off which it has never done before. And when i run full antivirus scans with panda it doesnt seem to take that long to scan and when its done it shuts itself off which i think is strange as it should come back with the scan results at least, even if it hasnt detected anything. Apart from those things it seems ok but i am rebooting often now due to the pc freezing or jamming up on me which isnt right either, so if you think you can help me find the problems there i would be greatful or is a reinstall of windows the best way aroound it? Cheerz Scott
We need to get the latest combofix.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"


Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Hi here is my combofix log that you requested followed by a new hijack this log. Really appreaciate your assistance. Cheerz Scott

ComboFix 08-01-03.3 - Scott & Maria 2008-01-03 16:44:10.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.435 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 14:52 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 18:30 . 2008-01-02 18:30 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-02 18:30 . 2008-01-02 18:30 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-02 18:07 . 2008-01-02 18:07 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2008-01-02 17:30 . 2008-01-02 17:30 d——– C:\Program Files\Activision Value
2008-01-01 13:57 . 2008-01-02 18:09 d——– C:\Program Files\The_Pirate_Bay
2008-01-01 13:57 . 2008-01-02 18:09 d——– C:\Program Files\Conduit
2008-01-01 10:20 . 2008-01-01 10:20 0 –a—— C:\WINDOWS\PowerReg.dat
2008-01-01 10:16 . 2008-01-01 10:16 d——– C:\Program Files\Infogrames
2008-01-01 10:05 . 2004-09-02 13:43 2,142,208 ——— C:\WINDOWS\UNNMP.exe
2008-01-01 10:05 . 2004-10-01 14:48 52,452 ——— C:\WINDOWS\UNNMP.cfg
2008-01-01 10:04 . 2004-03-02 17:37 125,184 ——— C:\WINDOWS\system32\drivers\imagesrv.sys
2008-01-01 10:04 . 2004-03-02 17:37 5,504 ——— C:\WINDOWS\system32\drivers\imagedrv.sys
2008-01-01 10:03 . 2001-07-09 11:50 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-01-01 10:02 . 2004-09-28 17:00 2,269,184 ——— C:\WINDOWS\UNNeroVision.exe
2008-01-01 10:02 . 2004-10-01 14:48 148,570 ——— C:\WINDOWS\UNNeroVision.cfg
2008-01-01 10:01 . 2004-07-26 17:16 1,568,768 ——— C:\WINDOWS\system32\ImagX7.dll
2008-01-01 10:01 . 2004-07-26 17:16 476,320 ——— C:\WINDOWS\system32\ImagXpr7.dll
2008-01-01 10:01 . 2004-07-26 17:16 471,040 ——— C:\WINDOWS\system32\ImagXRA7.dll
2008-01-01 10:01 . 2004-07-09 09:43 364,544 ——— C:\WINDOWS\system32\TwnLib4.dll
2008-01-01 10:01 . 2004-07-26 17:16 262,144 ——— C:\WINDOWS\system32\ImagXR7.dll
2008-01-01 10:01 . 2000-06-26 11:45 106,496 –a—— C:\WINDOWS\system32\TwnLib20.dll
2008-01-01 10:01 . 2001-06-26 08:15 38,912 ——— C:\WINDOWS\system32\picn20.dll
2007-12-31 17:02 . 2007-12-31 17:02 d——– C:\VundoFix Backups
2007-12-30 20:29 . 2007-12-30 20:29 d——– C:\Program Files\ProPilkki2
2007-12-30 17:17 . 2008-01-03 16:43 80 –a—— C:\WINDOWS\system32\drivers\netfltConfig.dat
2007-12-30 16:51 . 2007-12-30 18:29 163,856 –a—— C:\WINDOWS\system32\drivers\PavProc.sys
2007-12-30 16:51 . 2007-12-30 18:29 26,752 –a—— C:\WINDOWS\system32\drivers\ShldDrv.sys
2007-12-30 13:13 . 2007-12-30 13:13 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-30 13:13 . 2007-12-30 13:13 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-30 12:34 . 2008-01-03 16:41 69,776 —h—– C:\PANDA.RPT
2007-12-30 12:10 . 2007-12-30 12:10 d——– C:\Program Files\Panda Software
2007-12-30 11:59 . 2007-12-30 16:51 d——– C:\Program Files\Common Files\Panda Software
2007-12-29 20:11 . 2007-12-29 20:11 d——– C:\Program Files\CCleaner
2007-12-29 16:06 . 2007-12-29 16:06 d——– C:\Program Files\Trend Micro
2007-12-29 12:13 . 2007-12-29 12:17 d——– C:\Program Files\RegCure
2007-12-27 22:21 . 2007-12-29 14:31 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-27 19:58 . 2007-12-27 22:21 40,960 –a—— C:\WINDOWS\VM_STI .EXE
2007-12-27 18:24 . 2007-12-27 18:24 d——– C:\Program Files\Nsasoft
2007-12-27 17:16 . 2007-12-27 22:33 d——– C:\Program Files\QuickTime
2007-12-20 15:50 . 2007-12-20 15:50 d–h—– C:\WINDOWS\PIF
2007-12-12 10:38 . 2007-12-12 10:38 63 –a—— C:\WINDOWS\mdm.ini
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 13:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-02 22:07 ——— d—–w C:\Program Files\Spyware Doctor
2008-01-01 09:20 ——— d—–w C:\Program Files\GameSpy Arcade
2008-01-01 09:05 ——— d—–w C:\Program Files\Ahead
2008-01-01 09:01 ——— d—–w C:\Program Files\Common Files\Ahead
2007-12-30 17:29 98,304 —-a-w C:\WINDOWS\system32\pavipc.dll
2007-12-30 17:29 71,424 —-a-w C:\WINDOWS\system32\drivers\pavdrv51.sys
2007-12-30 17:29 245,760 —-a-w C:\WINDOWS\system32\TpUtil.dll
2007-12-30 17:29 208,896 —-a-w C:\WINDOWS\system32\PavSHook.dll
2007-12-30 16:10 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-30 13:41 ——— d—–w C:\Program Files\Windows Live Safety Center
2007-12-28 23:13 ——— d—–w C:\Program Files\Microsoft Works
2007-12-27 21:21 ——— d—–w C:\Program Files\DAEMON Tools
2007-12-23 07:30 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Skype
2007-12-09 12:12 ——— d—–w C:\Program Files\Sixtens Games Folder
2007-11-30 15:25 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-23 18:52 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Yahoo!
2007-11-23 13:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-23 13:39 ——— d—–w C:\Program Files\Yahoo!
2007-11-23 13:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-19 15:33 ——— d—–w C:\Program Files\Pettson1
2007-11-18 19:15 164,352 —-a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-11-18 19:14 ——— d—–w C:\Program Files\Jardinains!
2007-11-18 14:56 ——— d—–w C:\Program Files\Björne
2007-11-13 16:00 ——— d—–w C:\Program Files\Pettson3
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 18:37 2,288 —-a-w C:\Documents and Settings\Scott & Maria\Application Data\wklnhst.dat
2007-11-11 11:45 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\Microsoft Web Folders
2007-11-05 20:42 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\LimeWire
2007-11-05 20:39 ——— d—–w C:\Program Files\Common Files\Real
2007-11-05 20:37 ——— d—–w C:\Program Files\Apple Software Update
2007-11-04 08:50 ——— d—–w C:\Documents and Settings\Scott & Maria\Application Data\WeatherDPA
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 16:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-03-19 16:06 3,704,990 —-a-w C:\Program Files\GG-WINDOWS-894.EXE
2007-01-06 11:33 10,503,520 —-a-w C:\Program Files\sdsetup.exe
2006-08-13 17:16 880,779 —-a-w C:\Program Files\Eusing Free Registry CleanerSetup.exe
2007-03-27 16:20 5,330 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
—-a-w			90,112 2007-12-27 21:21:51  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart .exe
—-a-w			81,920 2007-12-27 21:21:32  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2007-12-27 21:21:24  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
—-a-w		   165,784 2007-12-27 18:59:35  C:\Program Files\DAEMON Tools\daemon .exe
—-a-w			94,208 2007-12-27 21:21:24  C:\Program Files\Dell\Media Experience\DMXLauncher .exe
—-a-w			68,856 2007-12-27 21:21:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   132,496 2007-12-27 21:21:21  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,117,184 2007-12-27 21:21:34  C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
—-a-w			95,800 2007-12-27 21:21:50  C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor .exe
—-a-w		   145,496 2007-12-27 21:21:53  C:\Program Files\Pinnacle\Studio 11\LaunchList2 .exe
—-a-w		   286,720 2007-12-27 19:00:25  C:\Program Files\QuickTime\QTTask .exe
—-a-w		 2,115,728 2007-12-29 15:03:13  C:\Program Files\Spyware Doctor\swdoctor .exe
—-a-w			40,960 2007-12-27 21:21:30  C:\WINDOWS\VM_STI .EXE
—-a-w			15,360 2007-12-29 13:31:47  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   122,940 2007-12-27 21:21:25  C:\WINDOWS\system32\DLA\DLACTRLW .EXE


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-12-29 16:05 2115728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 11:00 282624 C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 20:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 20:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 20:12 86016]
"APVXDWIN"="C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\APVXDWIN.exe" [2005-03-31 20:08 315392]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00 15360]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-12-29 16:05 2115728]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-11-10 16:34:00]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 09:15:56]
MiniMavis.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe [2006-12-29 20:43:02]
Personal.lnk - C:\Program Files\Personal\bin\Personal.exe [2007-02-03 12:49:33]

R0 netflt;Panda Preventium Driver.;C:\WINDOWS\system32\Drivers\netflt.sys [2005-10-21 11:06]
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys [2007-12-30 18:29]
R2 Pavkre;Panda Pavkre;"C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe" [2005-08-30 14:51]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2007-12-30 18:29]
R2 PavProt;Panda PavProt;"C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe" [2005-08-30 14:51]
R2 PREVSRV;Panda Preventium+ Service;"C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe" [2004-10-30 17:43]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [2005-07-27 14:11]
S3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-01-03 09:51:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-03 15:14:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-03 13:45:05 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-03 04:18:03 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 16:49:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-01-03 16:50:29
.
2007-12-12 12:08:32 — E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:54:31 PM, on 3/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AvltMain.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Apvxdwin.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\WebProxy.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: Personal.lnk = C:\Program Files\Personal\bin\Personal.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.fujidirekt.se/aurigma/ImageUploader4.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.7.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
O23 - Service: Panda Pavkre (Pavkre) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
O23 - Service: Panda PavProt (PavProt) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv51.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

–
End of file - 10299 bytes
  • 1.Download RenV.exe by sUBs to your desktop
    2. Double click on it to run it
    It will search your system drive looking for any modified .exe file and will produce a log for you named log.txt


  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as Log.txt (Overwrite the existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart .exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
C:\Program Files\DAEMON Tools\daemon .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor .exe
C:\Program Files\Pinnacle\Studio 11\LaunchList2 .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\Spyware Doctor\swdoctor .exe
C:\WINDOWS\VM_STI .EXE
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\DLA\DLACTRLW .EXE

[external image: Posted Image]

Refering to the picture above, drag Log.txt into RenV.exe and attach the resulting report to your reply.

Reboot then do this


* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Hi LDT, Sorry its taken me so long to get back to you but i had to wipe my harddrive and reload all over again. I was trying to avoid it but what ever got a hold of my system left me no choice at all. Thanks heaps for your help, i will continue to use the site and have applied for the classroom so i hope they let me in to start learning more and helping others out like you have helped me out. Will also make a donation. Cheerz Scott

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI